Engineering Papers⌕ Search

SEARCH · Engineering Papers

Results for “attack modeling”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

At least 181 records · Page 10

High-fidelity model-driven deception platform for cyber-physical systems

Methods are described for protecting a cyber-physical system against a potential attacker of the system. The methods include a method of generating a plurality of examples for a training data set and training a system model using the training data set to generate a decoy configured to generate a synthetic output that mimics historical outputs generated by the system for a given historical system context. Also described is a method including receiving a system context of a cyber-physical system; receiving an inquiry into the system by a potential attacker; applying a system model to the system context and the inquiry; obtaining from the system model a synthetic output that mimics how a component of the system would respond to the inquiry given the system context; and providing the synthetic output to the potential attacker.

Edgar, Thomas W.↗

Universal Fourier Attack for Time Series

A wide variety of adversarial attacks have been proposed and explored using image and audio data. These attacks are notoriously easy to generate digitally when the attacker can directly manipulate the input to a model, but are much more difficult to implement in the real world. In this paper we present a universal, time invariant attack for general time series data such that the attack has a frequency spectrum primarily composed of the frequencies present in the original data. The universality of the attack makes it fast and easy to implement as no computation is required to add it to an input, while time invariance is useful for real world deployment. Additionally, the frequency constraint ensures the attack can withstand filtering defenses. We demonstrate the effectiveness of the attack on two different classification tasks through both digital and real world experiments, and show that the attack is robust against common transform-and-compare defense pipelines.

97 MATHEMATICS AND COMPUTING↗

Transfer Learning using Denoising Auto-Encoders for Cellular-Level Annotation of Tumor in Pathology Slides

Adversarial examples can produce altered classifications using only seemingly innocuous, imperceptible perturbations to the original image. The imperceptibility of adversarial perturbations suggests that the corresponding classifiers use decision criteria different than those of a human. In a medical setting, inexplicable decision criteria confound a pathologist’s willingness to trust machine-generated annotations. Here, we analyze denoising tumor detection models to see if they are robust to imperceptible adversarial perturbations. Moreover, to be more fully trusted by pathologists, we require tumor detectors that generate interpretable annotations which segment pathology slides into tumorous and normal regions at the cellular level. We therefore compare transfer learning based on two different autoencoder architectures, one derived from a deep denoising bottleneck autoencoder and one from an over-complete sparse autoencoder. Both autoencoders were first trained in an unsupervised manner on a set of pathology slides drawn from the Camelyon16 dataset. The latent representations produced by each autoencoder were then passed to separate neural networks that were trained in a supervised manner on binary tumor-normal masks generated by pathologists at cellular resolution. Both tumor detectors supported better than 90% AUC PR as measured by the area under the precision/recall curve on a held-out pathology slide. To assess the underlying decision criteria used by both tumor detectors, we constructed imperceptible adversarial examples which reduced the AUC PR of both models to less than 70%. Random noise of the same amplitude had almost no effect on the AUC PR of either model. Additionally, each tumor detector was resistant to adversarial “transfer” attacks targeting the other. The adversarial perturbations showed strong characteristic differences: the deep denoising models perturbations were a very diffuse, seemingly unrecognizable pattern while the sparse coding models perturbations showed traces of tissue cells.

47 OTHER INSTRUMENTATION↗

Data trustworthiness signatures for nuclear reactor dynamics simulation

With the increased reliance on digitization in industrial control systems, the need for effective monitoring techniques has risen dramatically. Specifically, there is now a growing concern about the so-called false data injection (FDI) attacks. These attacks aim to alter the raw sensors’ data to cause malicious outcomes. Any serious FDI algorithm is based on an intimate knowledge of the system and its associated physics models, which renders conventional outlier/anomaly detection techniques almost obsolete in the face of such attacks. Thus, a critical need has emerged to develop a new class of defense methods that are capable of detecting FDI attacks under the assumption that the attacker has a strong familiarity with the system and its physics modeling. This class of defense methods are denoted by model-based defenses which are premised on the assumption that the attacker, while having a good understanding of the system, does not have full privileged access to all proprietary data and historical records of operation. However, (s)he is assumed to be capable of learning system behavior using self-learning techniques during an initial lie-in-wait period. To defend against this scenario, we propose a new model-based randomized window algorithm that searches time-series data for signatures that can serve as classifiers between normal and FDI scenarios. The classifiers are based on the correlations between the dominant degrees of freedom (DOFs) and the less-dominant DOFs (expected to be very sensitive to the system details that are unknown to the attacker). For demonstration, RELAP5 models are employed to calculate representative nuclear reactor behavior during a number of transient scenarios. Finally, falsified data are injected into the RELAP5-simulated behavior, and the proposed signature-identification algorithm is employed to detect the injected data.

73 NUCLEAR PHYSICS AND RADIATION PHYSICS↗

Universal Fourier Attack for Time Series

A wide variety of adversarial attacks have been proposed and explored using image and audio data. These attacks are notoriously easy to generate digitally when the attacker can directly manipulate the input to a model, but are much more difficult to implement in the real-world. In this paper we present a universal, time invariant attack for general time series data such that the attack has a frequency spectrum primarily composed of the frequencies present in the original data. The universality of the attack makes it fast and easy to implement as no computation is required to add it to an input, while time invariance is useful for real-world deployment. Additionally, the frequency constraint ensures the attack can withstand filtering. We demonstrate the effectiveness of the attack in two different domains, speech recognition and unintended radiated emission, and show that the attack is robust against common transform-and-compare defense pipelines.

97 MATHEMATICS AND COMPUTING↗

Dynamical Low-Rank Compression of Neural Networks with Robustness under Adversarial Attacks

Deployment of neural networks on resource-constrained devices demands models that are both compact and robust to adversarial inputs. However, compression and adversarial robustness often conflict. In this work, we introduce a dynamical low-rank training scheme enhanced with a novel spectral regularizer that controls the condition number of the low-rank core in each layer. This approach mitigates the sensitivity of compressed models to adversarial perturbations without sacrificing clean accuracy. The method is model- and data-agnostic, computationally efficient, and supports rank adaptivity to automatically compress the network at hand. Extensive experiments across standard architectures, datasets, and adversarial attacks show the regularized networks can achieve over 94 compression while recovering or improving adversarial accuracy relative to uncompressed baselines.

Schotthoefer, Steffen [ORNL] (ORCID:00000002156965↗

Identification of a Delay Attack in the Secondary Control of Grid-Tied Inverter Systems

This work is developed for the identification of a denial-of-service cyberattack on the secondary controller of inverter systems which is connected to the power grid. The identification is made through the dynamic response of the reactive power (Q) of the system under attack. By observing the dynamic characteristic of Q, it is possible to correlate the attack with the nominal response of the hierarchical controller. The article shows that the occurrence of the attack can be identified through a supervisory control that runs a model in parallel. The article argues that after an early identification of the attack, a local controller can take action to mitigate its effects on the system’s response.

Roig Greidanus, Mateo D.↗

ASK: Adversarial Soft k-Nearest Neighbor Attack and Defense

K-Nearest Neighbor (kNN)-based deep learning methods have been applied to many applications due to their simplicity and geometric interpretability. However, the robustness of kNN-based deep classification models has not been thoroughly explored and kNN attack strategies are underdeveloped. In this paper, we first propose an Adversarial Soft kNN (ASK) loss for developing more effective kNN-based deep neural network attack strategies and designing better defense methods against them. Our ASK loss provides a differentiable surrogate of the expected kNN classification error. It is also interpretable as it preserves the mutual information between the perturbed input and the in-class-reference data. We use the ASK loss to design a novel attack method called the ASK-Attack (ASK-Atk), which shows superior attack efficiency and accuracy degradation relative to previous kNN attacks on hidden layers. We then derive an ASK-Defense (ASK-Def) method that optimizes the worst-case ASK training loss. Experiments on CIFAR-10 (ImageNet) show that (i) ASK-Atk achieves ≥13% (≥ 13% ) improvement in attack success rate over previous kNN attacks, and (ii) ASK-Def outperforms the conventional adversarial training method by ≥ 6.9% (≥ 3.5% ) in terms of robustness improvement. Relevant codes are available at https://github.com/wangren09/ASK .

97 MATHEMATICS AND COMPUTING↗

Structural dissection of sequence recognition and catalytic mechanism of human LINE-1 endonuclease

Abstract Long interspersed nuclear element-1 (L1) is an autonomous non-LTR retrotransposon comprising ∼20% of the human genome. L1 self-propagation causes genomic instability and is strongly associated with aging, cancer and other diseases. The endonuclease domain of L1’s ORFp2 protein (L1-EN) initiates de novo L1 integration by nicking the consensus sequence 5′-TTTTT/AA-3′. In contrast, related nucleases including structurally conserved apurinic/apyrimidinic endonuclease 1 (APE1) are non-sequence specific. To investigate mechanisms underlying sequence recognition and catalysis by L1-EN, we solved crystal structures of L1-EN complexed with DNA substrates. This showed that conformational properties of the preferred sequence drive L1-EN’s sequence-specificity and catalysis. Unlike APE1, L1-EN does not bend the DNA helix, but rather causes ‘compression’ near the cleavage site. This provides multiple advantages for L1-EN’s role in retrotransposition including facilitating use of the nicked poly-T DNA strand as a primer for reverse transcription. We also observed two alternative conformations of the scissile bond phosphate, which allowed us to model distinct conformations for a nucleophilic attack and a transition state that are likely applicable to the entire family of nucleases. This work adds to our mechanistic understanding of L1-EN and related nucleases and should facilitate development of L1-EN inhibitors as potential anticancer and antiaging therapeutics.

59 BASIC BIOLOGICAL SCIENCES↗

Advanced Reactor Cyber Analysis and Development Environment (ARCADE) for System-Level Design Analysis

Cybersecurity is a persistent concern to the safety and security of Nuclear Power Plants (NPPs), but has lacked data-driven, evidence-based research. Rigorous cybersecurity analysis is critical for the licensing of advanced reactors using a performance-based approach. One tool that enables cybersecurity analysis is modeling and simulation. The nuclear industry makes extensive use of modeling and simulation throughout the decision process but lacks a method to incorporate cybersecurity analysis with existing models. To meet this need, the Advanced Reactor Cyber Analysis and Development Environment (ARCADE) was developed. ARCADE is a suite of publicly available tools that can be used to develop emulations of industrial control system devices and networks and integrate those emulations with physics simulators. This integration of cyber emulations and physics models enables rigorous cyber-physical analysis of cyber-attacks on NPP systems. This report provides an overview of key considerations for using ARCADE with existing physics models and demonstrates ARCADE’s capabilities for cybersecurity analysis. Using a model of the Small Modular Advanced High Temperature Reactor (SmAHTR), ARCADE was able to determine the sensitivity of the primary heat exchangers (PHX) to coordinated cyber-attacks. The analysis determined that while the PHX’s failures cause disruption to the reactor, they did not cause any safety limits to be exceeded because of the plant design, including passive safety features. Further development of ARCADE will enable rigorous, repeatable, and automated cyber-physical analysis of advanced reactor control systems. These efforts will also help reduce regulatory uncertainty by presenting similar types of cybersecurity analyses in a common format, driving standard approaches and reporting.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Securing Federated Learning Against Active Reconstruction Attacks

Federated Learning (FL) has amassed notable attention for its ability to preserve user privacy while emphasizing the retainment of model training efficiency. Due to this potential, FL has been integrated in many domains, such as healthcare, finance, law, and industrial engineering, where data cannot be easily exchanged due to sensitive information and strict privacy laws. However, current research has indicated that FL protocols are easily compromised by active data reconstruction attacks employed by actively dishonest servers. The malicious modification of global model parameters allows an actively dishonest server to obtain a direct copy of users’ private data via gradient inversion. Here, this class of attacks is highly underexplored and continues to be a major challenge due to the intense threat model. In this paper, we propose OASIS as a scalable and modality-agnostic defense based on data augmentation that counteracts active data reconstruction attacks while preserving model performance. To generalize our defense, we uncover the intuition behind gradient inversion that enables these attacks and theoretically establish the conditions by which the defense can be considered robust regardless of attack design. From this, we formulate our defense with data augmentation that illustrates its ability to undermine the attack principle. We evaluate OASIS on five real-world datasets–two image-based (ImageNet and CIFAR100) and three text-based (Wikitext, Stack Overflow, and Shakespeare)–which span diverse uses cases such as vision tasks and language modeling. Comprehensive evaluations on these datasets exhibit the efficacy of OASIS and highlight its feasibility as a solution.

97 MATHEMATICS AND COMPUTING↗

Analyzing the Effects of Cyberattacks on Distribution System State Estimation: Preprint

Key components of power systems—such as energy management systems, automatic generation control, and state estimation—are under serious vulnerability from cyber attacks. Cyber threats in electric grids have increased significantly because of the increased interconnectivity of supervisory control and data acquisition systems and public network infrastructure. As the penetration level of distributed energy resources increases, it is imperative to employ system-monitoring techniques such as state estimation for the reliable operation of distribution systems. Recently, multiple methods have been developed that exploit the low rank property of distribution system state matrix and are robust to bad data, such as matrix completion. This paper analyzes the impact of various realistic cyber attack scenarios on matrix completion. Realistic cyber attack scenarios are converted into data corruption models that are used in an extensive simulation of a custom IEEE 123-bus system.

41 EE - Solar Energy Technologies Office (EE-4S)↗

On the competitive antagonism effect in combined chloride-sulfate attack: A numerical exploration

Highlights: • A chemo-physical-mechanical method based on thermodynamic modelling is implemented. • The contradicting findings from reported experiments are numerically explored. • The competitive antagonism effect is time-dependent rather than a conclusive term. • The competitive antagonism effect is quantifiable with a novel assessment criterion. It is of tremendous difficulty to draw a conclusive verdict on the complex process of mutual interference regarding the combined chloride-sulfate attack on concrete, where many have explored the topic, but contradicting results have been reported. In this paper, by taking advantages of the chemo-physical-mechanical method, based on the robust technique of thermodynamic modelling, the competitive antagonism effect in combined chloride-sulfate attack is investigated. Firstly, a range of reported tests are numerically modelled to demonstrate the effectiveness of the employed method in interpreting those opposing and diverse experimental outcomes. More importantly, a fresh conjecture incorporating a novel assessment criterion for the competitive antagonism effect is proposed and supported through a carefully designed illustrative example. Based on the numerical exploration, unique findings and implications for future engineering practices are revealed.

36 MATERIALS SCIENCE↗

Enabling Dynamic Probabilistic Risk Assessment of Physical Security Using EMRALD and MAAP

The optimization of physical security in nuclear power plants requires sophisticated methodologies that integrate operator actions and plant behavior through advanced simulation tools. To address this, Idaho National Laboratory [JL2.1]has developed the Modeling and Analysis for Safety and Security using the Dynamic EMRALD Framework (MASS-DEF) methodology, an approach that integrates force-on-force simulations, dynamic probabilistic risk assessment, and thermal-hydraulics modeling [JL3.1]to enhance security planning while reducing costs. We developed a tool that produces reduced order models using thermal hydraulic simulations from the Modular Accident Analysis Program (MAAP) [1]. These models can quickly evaluate reactor core behavior during attack simulations, and in so doing, address two barriers of traditional methods: (1) MAAP simulations are computationally intensive, and (2) attack scenarios must be run in a secure environment, which complicates analysis and validation. By precomputing scenario outcomes for a small number of modified parameters, the reduced order model significantly decreases the computational cost and enables offsite review of the results.

22 - GENERAL STUDIES OF NUCLEAR REACTORS↗

Operational resilience of additively manufactured parts to stealthy cyberphysical attacks using geometric and process digital twins

Cyberphysical attacks on the digital backbone of Additive Manufacturing (AM) can compromise the printed part’s functionality. They can alter features in the digital geometry to introduce geometric defects (e.g., missing fillets) or alter process parameters to create local defects (e.g., voids). Addressing the downtime, waste, and quality deterioration associated with existing solutions requires operational resilience, i.e., rapid elimination or disruption of defect formation (to retain part function) without production stoppage or part disposal (to retain yield). This need is unmet due to the inherently unpredictable nature of attack-induced alterations, lack of access to the original geometric model for identification of altered geometric features, and in-process imposition of unknown process dynamics via attack-driven alteration of real-time-uncontrolled (or exogenous) parameters. This work establishes the above-mentioned operational resilience for the first time by creating two Digital Twins (DT). The Geometric DT (Geo-DT) is based on a unique physical-field-driven soft sensor and topology optimization method. The Process Digital Twin (Pro-DT) combines local defect quantification with a novel Reinforcement Learning formulation and training method. The importance of these methodological advances and the scalability of our approach are examined on a real AM testbed. It is shown that Geo-DT can correct geometric defects without access to the original digital geometry or explicit knowledge of attack-altered geometric features. Further, Pro-DT can accelerate real-time disruption of local defects despite attack-driven imposition of unknown process dynamics. We discuss how our framework goes beyond the contemporary focus on pre-attack security and in-attack detection towards resilience for AM and beyond.

Additive Manufacturing↗

Autonomous System Inference, Trojan, and Adversarial Reprogramming Attack and Defense (Final)

In the world of ever-advancing technology, Autonomous Systems (AS) find extensive application, bolstering functionalities of critical infrastructures such as nuclear power plants. These systems, however, are increasingly becoming a target for nefarious activities, namely through inference attacks, trojan attacks, and adversarial reprogramming. This paper delves into a comprehensive exploration of machine learning (ML)-driven autonomous control systems within advanced nuclear reactor designs, revealing the vulnerabilities and proposing strategies for defense against potential cyber-attacks. Advanced cyber-attacks against critical infrastructure and the energy sector are becoming more common. With the invention of autonomous control systems (ACS) within advanced nuclear reactor designs, system designers, reactor operators, and regulators must consider cybersecurity during the design and operational phases. This article provides a cyber threat assessment of machine learning (ML)- based digital twinning (DT) technologies in the context of advanced reactor ACS. A cyber-physical testbed was created to emulate nuclear reactor digital instrumentation and controls (I&C) and act as a basis for the ACS. The ACS was designed as two plant-level DTs predicting reactor malfunctions and determining control actions and two component-level DTs responsible for classifying component states and forecasting component inputs and outputs (I/O). Two duplicate ACS designs– one using a traditional ML framework and one using an automated ML (AutoML) framework– were created and tested against cyber-attacks on training data, real-time process data, and ML model architectures to determine their respective qualitative cyber-risk in terms of likelihood and impact. Both frameworks showed similar cyber-resilience against training, real-time, and ML architecture attacks, proving that neither is inherently more secure. Recommended safeguard and security measures are posed to system designers, reactor operators, and regulators to maintain the cybersecurity of ML-based DT technologies such as ACS, prompting a holistic view of shared responsibility for maintaining cyber-secure ML-based systems. As global reliance on generation III reactors begins to be critically assessed, the evolution towards advanced reactor systems utilizing digital instrumentation and controls (I&C) becomes not merely preferable, but essential. The integration of semi and fully autonomous control systems (ACS), powered by digital I&C and machine learning (ML)-based digital twinning (DT) technologies, emerges as a potent strategy to mitigate operations and maintenance costs, thereby enhancing the economic feasibility of novel reactor designs. However, with a staggering 500% and 380% increase in cyber-attacks reported against the energy sector by the United States Department of Energy (DoE) and the European Union respectively, a surge in cyber vulnerabilities specifically targeting the nuclear industry has been 2 markedly observed. Notable incidents, such as the W32.Ramnit spyware infiltration at the Gundremmingen nuclear power plant in Germany and the Dtrack spyware intrusion at the Kudankulam nuclear power plant in India, while not directly compromising core industrial control systems (ICS), underscore a compelling necessity to fortify cybersecurity protocols in safeguarding reactor systems against increasingly adept digital adversaries. In light of this, our investigation extends beyond conventional cybersecurity parameters, diving into the intricate web of potential vulnerabilities woven into ML-based DTs and ACS in advanced reactor systems. A crafted cyber-physical testbed and preliminary ACS were devised to act as a mirror, reflecting potential configurations of advanced reactor control designs. Moreover, this study is intertwined with a scrutinization of ML models, developed either through conventional, manually tuned methodologies or via automated means through AutoML, probing into their cyber-risk profiles within operational technology (OT) environments. Expanding on this, two distinct ACS blueprints were forged – one navigating through the corridors of traditional ML and the other traversing the path of AutoML – in an effort to holistically encapsulate the considerations pivotal to ML-based DT control system design. Employing the SANS Institute Industrial Control System (ICS) Kill Chain and the MITRE ATT&CK Tactics, Techniques, and Procedures (TTP) framework, a structured analysis was conducted, launching three targeted attacks against the training dataset, real-time dataset, and ML models, therein dissecting the potential cyber-attack implications against both ML frameworks within an ACS milieu. It is essential to note that three distinct categories of attacks were conducted against both ACS configurations, each encompassing three distinct ML-based DTs, cumulating in a total of 18 varied attacks. This exploration extends into the realms of Autonomous System Inference, Trojan, and Adversarial Reprogramming Attack and Defense, unraveling vulnerabilities, and opportunities for fortified defenses against such intrusions, particularly where ML-driven technologies, and by extension, ACS, are deployed. Final recommendations, articulated through a lens of security, safeguard, and implementation considerations, are presented for both traditional and AutoML models, anchoring upon the existing knowledge landscape and ML-based DT modeling for ACS, and are offered as a beacon to guide the nuclear industry through the intricate cybersecurity challenges that lie ahead.

22 GENERAL STUDIES OF NUCLEAR REACTORS↗

Modeling Clustered DNA Damage by Ionizing Radiation Using Multinomial Damage Probabilities and Energy Imparted Spectra

Simple and complex clustered DNA damage represent the critical initial damage caused by radiation. In this paper, a multinomial probability model of clustered damage is developed with probabilities dependent on the energy imparted to DNA and surrounding water molecules. The model consists of four probabilities: (A) direct damage of sugar-phosphate moieties leading to SSB, (B) OH− radical formation with subsequent SSB and BD formation, (C) direct damage to DNA bases, and (D) energy imparted to histone proteins and other molecules in a volume not leading to SSB or BD. These probabilities are augmented by introducing probabilities for the relative location of SSB using a ≤10 bp criteria for a double-strand break (DSB) and for the possible success of a radical attack that leads to SSB or BD. Model predictions for electrons, 4He, and 12C ions are compared to the experimental data and show good agreement. Thus, the developed model allows an accurate and rapid computational method to predict simple and complex clustered DNA damage as a function of radiation quality and to explore the resulting challenges to DNA repair.

Biochemistry & Molecular Biology↗

Cybersecurity Enhancement for Multi-Infeed High-Voltage DC Systems

Composed of multiple two-terminal high-voltage DC (HVDC) transmission systems, a multi-infeed HVDC (MIDC) system exchanges massive power among multiple asynchronous AC systems. However, as an intrinsically cyber-physical system, an MIDC system could suffer from cyber-attacks, leading to massive power mismatches in multiple AC systems, and resulting in catastrophic consequences. Since the sequential responses of an MIDC system and interconnected AC systems are in different timescales, this paper first establishes a two-timescale model to evaluate the sequential impacts caused by cyber-attacks. Then, an event-triggered cyber-defense strategy is proposed to enhance the cybersecurity of an MIDC system by mitigating multiple non-simultaneous cyber-attacks. Whenever new cyber-attack events occur, the proposed cyber-defense strategy, which is mathematically modeled as a mixed-integer quadratic programming problem, is executed on-line and updated in an event-triggered manner. Here, simulation results on an MIDC system demonstrate that the low-cost and almost blind cyber-attacks can cause severe frequency deviations, and the proposed strategy can mitigate multi-cyber-attacks effectively.

24 POWER TRANSMISSION AND DISTRIBUTION↗